Threat Intelligence

Threat IntelligenceNew

A built-in Threat Intelligence Platform that ingests live IOC feeds from URLhaus, Feodo Tracker, OpenPhish, AlienVault OTX, and AbuseIPDB — enriching your security data with real-world threat context across every module.

Threat Intelligence

Live IOC feeds, enrichment, and threat lookup

What it does

Key capabilities

Live Feed Ingestion

Automatically pulls IOCs from URLhaus, Feodo Tracker botnet C2 IPs, OpenPhish, AlienVault OTX, and AbuseIPDB on a configurable schedule.

IOC Database

Maintains a searchable, filterable database of all active Indicators of Compromise — IPs, domains, URLs, and file hashes — per client.

Real-Time Lookup

Instantly check any IP, domain, URL, or hash against your live IOC database from anywhere in the platform.

Cross-Module Enrichment

TIP match badges appear automatically in HakScout, Investigations, and other modules — surfacing threat context where you need it.

Manual IOC Entry

Add custom IOCs from your own threat intelligence sources, incident findings, or vendor advisories.

IOC Dashboard

Visual dashboard showing IOC counts by type and severity, feed sync status, and recently added indicators.

Highlights

Why Threat Intelligence?

  • URLhaus, Feodo Tracker, OpenPhish — free feeds, no key required
  • AlienVault OTX and AbuseIPDB with API key
  • IOC match badges surfaced across HakScout, Investigations and more
  • Per-client IOC database — no cross-tenant data mixing
  • MERGE upserts keep IOC data current without duplication
Included in OneView

Threat Intelligence is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210

See Threat Intelligence in action

Request a personalised demo and we'll show you exactly how Threat Intelligence works within your environment.